Hello guys,
I am working on some of the new java exploits in the wild. However, everything goes fine, unless creating the meterpreter session.
for instance, I used java rhino exploit and after starting the server and launching the vulnerable website, all I've got is as follows:[*] 10.1.41.3 java_rhino - Java Applet Rhino Script Engine Remote Code Execution handling request[*] 10.1.41.3 java_rhino - Sending Applet.jar

In a similar situation, I've started to use java_jre17_jmxbean exploit. Although it started the server and launched the exploit, it still doesn't create the meterpreter session.

Just for the records, I've set the LPORT and LHOST to the attacker's port and attacker's IP address, respectively. So, everything is okay, unless the meterpreter session! :confused:

My victims run both Win7 and Win XP SP3.

02-05-2013, 01:51 PM

Atomix

Re: Meterpreter doesn't create its session

Are you sure java is installed on the victims?

02-24-2013, 06:11 PM

Onedevil420

Re: Meterpreter doesn't create its session

I am also facing this Problem. In my case java is installed in victim's machine

02-25-2013, 04:58 AM

jnpa123

Re: Meterpreter doesn't create its session

Are you sure they're running vulnerable java versions????? Any antivirus or firewall installed????

02-25-2013, 06:34 PM

Onedevil420

Re: Meterpreter doesn't create its session

The firewall of the victim's machine is off and still it's not working it like this

Yah and i still think you're not using a vulnerable java version or an antivirus
I only asked about the firewall because in a quite specific situation it could be blocking it and the other two are pretty obvious

02-27-2013, 10:44 AM

Onedevil420

Re: Meterpreter doesn't create its session

I m not using the antivirus on victim's machine and I don't know where I found the vanurable version of java.

02-27-2013, 02:14 PM

jnpa123

Re: Meterpreter doesn't create its session

Well if there are no AV's/firewalls then im pretty sure you're not using a vulnerable version.
Just check what version(s) are affected by the exploit you are trying to use and search for it in the internet, here you can find some old versions http://www.oldapps.com/java.php

02-27-2013, 05:50 PM

zimmaro

Re: Meterpreter doesn't create its session

hi :)
I did a test in this way ...... but I do not know if it is the correct way!